October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

How to Patch SharePoint ToolShell Vulnerabilities and Verify the Fixes

Patch the correct on-premises SharePoint Server edition, complete machine-key rotation and IIS restarts across the farm, then investigate compromise separately from update status.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For on-premises SharePoint Server, patch every farm server with the update that matches its edition, include the required language-pack updates for SharePoint Server 2016 and 2019, then rotate ASP.NET machine keys and restart IIS across the farm. Verify patch status and possible compromise separately: a successful update does not prove that an attacker who accessed the farm earlier has been removed. Microsoft says SharePoint Online in Microsoft 365 is not affected by CVE-2025-53770 or CVE-2025-53771.

What ToolShell affects—and what it does not

Microsoft described active attacks in July 2025 against on-premises SharePoint Server involving CVE-2025-53770 and CVE-2025-53771, related to the earlier CVE-2025-49704 and CVE-2025-49706. In Microsoft’s threat-intelligence description, CVE-2025-53770 is the remote-code-execution vulnerability, while CVE-2025-53771 is a security-bypass/path-traversal vulnerability. Microsoft’s guidance says these vulnerabilities affect on-premises SharePoint Server; SharePoint Online in Microsoft 365 is not impacted.

The active-attack reporting describes the situation when Microsoft published its guidance in July 2025. It does not establish the exploitation status on October 4, 2026. Treat the incident as a reason to check your environment and current Microsoft guidance, not as evidence that attacks are happening now.

Which SharePoint update applies to your farm?

Use the package path for the installed SharePoint Server edition, not a KB number chosen from another edition. The following are the July 2025 security updates and builds identified in Microsoft guidance; they are not confirmation that no later update has superseded them. Before deployment, check Microsoft’s current update guidance against the farm’s edition, language packs, and servicing state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Installed edition July 2025 security update Build identified by Microsoft Support Additional language-pack update
SharePoint Server Subscription Edition KB5002768 16.0.18526.20508 Not stated for this package in the cited guidance
SharePoint Server 2019 KB5002754 16.0.10417.20037 KB5002753; Microsoft says to install both updates
SharePoint Server 2016 KB5002760 16.0.5513.1001 KB5002759

Microsoft’s support articles describe these KBs as addressing SharePoint Server remote-code-execution and spoofing vulnerabilities and refer to CVE-2025-53770 and CVE-2025-53771. The build numbers identify the packages documented in those articles; use Microsoft’s live guidance to confirm what is applicable to a farm being serviced now.

Patch the farm and complete the required follow-up

Plan the change across the whole SharePoint farm. Applying an update to only one server, or installing a package without its required companion update, leaves the patch state incomplete.

  1. Inventory the farm. Record every SharePoint server, its edition and installed build, the language packs present, and its current servicing state. Match each server to Microsoft’s currently applicable update instructions.
  2. Install the edition-specific security update. Apply the appropriate Microsoft package to the farm. Microsoft’s advisory describes the security updates as cumulative. For SharePoint Server 2016 and 2019, install both updates listed for the edition, including the language-pack update.
  3. Check AMSI and antivirus coverage. Confirm that Antimalware Scan Interface (AMSI) is enabled and correctly configured on each applicable server. Where HTTP Request Body scanning is available, Microsoft recommends Full Mode and Defender Antivirus on all SharePoint servers. AMSI integration was enabled by default in the September 2023 security update for SharePoint Server 2016 and 2019, and in the SharePoint Subscription Edition 23H2 feature update; verify the actual farm configuration rather than relying on those defaults. If AMSI cannot be enabled, Microsoft’s guidance recommends disconnecting the server from the internet until it is updated. If disconnection is not possible, restrict unauthenticated access through an authenticated VPN, proxy, or gateway.
  4. Rotate the ASP.NET machine keys. Microsoft’s PowerShell guidance names Set-SPMachineKey -WebApplication <SPWebApplicationPipeBind> to generate a key and Update-SPMachineKey -WebApplication <SPWebApplicationPipeBind> to deploy it. Run the commands in accordance with Microsoft’s instructions for the relevant web applications and record completion.
  5. Restart IIS on every SharePoint server. After key rotation, Microsoft’s instructions specify iisreset.exe on each SharePoint server. Track completion server by server; restarting only one machine is not a farm-wide restart.
  6. Maintain detection coverage. Deploy Defender for Endpoint or an equivalent solution to detect and block post-exploitation activity. This is a detection and protection layer, not a replacement for installing the SharePoint update.

Verify patch state separately from compromise state

“Patched” and “not compromised” are different conclusions. Keep separate records for package installation and post-update actions, and for the results of your security investigation.

Patch-state checks

  • For every farm server, compare its edition, installed build, and update inventory with the applicable Microsoft update documentation. For 2016 and 2019, confirm the language-pack update as well as the primary update.
  • Confirm and record farm-wide completion of machine-key rotation and the IIS restart on every SharePoint server.
  • Verify AMSI configuration, HTTP Request Body Full Mode where available, and antivirus coverage rather than assuming those controls are enabled.
  • Where available, review Microsoft Defender Vulnerability Management exposure and remediation status, including Evidence of Exploitation tags. Visibility depends on the organization’s Defender capabilities and available telemetry; an absence of a tag is not proof that the farm was never exploited.

Compromise checks

  • Review Defender Antivirus detections and Defender for Endpoint alerts identified in Microsoft’s guidance. Relevant alert types include possible web-shell installation, possible exploitation of SharePoint vulnerabilities, suspicious IIS worker behavior, and suspicious .NET assembly loading. Microsoft cautions that alerts can also arise from unrelated activity, so investigate rather than treating an alert alone as proof.
  • Hunt across IIS, SharePoint ULS, Windows event, PowerShell, and available Sysmon logs. The Cyber Security Agency of Singapore’s July 24, 2025 guide highlights POST requests to /_layouts/15/ToolPane.aspx?DisplayMode=Edit with a Referer of /_layouts/SignOut.aspx, later requests to web shells such as spinstall0.aspx, and suspicious files in SharePoint TEMPLATELAYOUTS directories. Treat these as indicators to investigate, not standalone proof of compromise.
  • Use Microsoft’s Advanced Hunting guidance with a historical window suitable for the investigation. Its examples cover up to 30 days of events; available history depends on telemetry retention and the tools configured in your organization. Preserve relevant evidence and assess the full farm and connected environment, not just the server where an alert first appeared.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If the farm may have been compromised

A server compromised before patching may remain compromised after the update. Patching closes the vulnerability addressed by the update; it does not establish that an attacker has lost access, that a web shell or other persistence has been removed, or that connected systems are safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
  1. Use an incident-response process. Identify and scope suspicious activity, contain affected systems, and preserve relevant evidence before changes that could destroy it.
  2. Remove persistence and investigate the environment. Address web shells and other attacker footholds, then assess the wider farm and connected systems. Do not treat clean patch inventory as evidence that this work is complete.
  3. Recover from a trusted state when necessary. The Cyber Security Agency of Singapore’s guidance says patching alone is insufficient for an already-compromised environment and describes rebuilding or restoring from a verified clean backup as recovery options. Choose recovery actions based on the investigation and the integrity of the available backup.

If indicators point to compromise, involve your organization’s incident-response team or qualified SharePoint recovery support. Coordinate containment and recovery with the teams responsible for the farm and connected infrastructure.

What a completed verification should document

  • The edition, build, applicable update packages, and language-pack update status for every farm server.
  • Completion of machine-key rotation and the post-rotation IIS restart on every SharePoint server.
  • AMSI, scanning-mode where available, and antivirus coverage checks.
  • The alert, log, hunting, and filesystem review performed, the time window covered, and any findings that require containment or recovery.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.